VB Blog

VB2017 video: Turning Trickbot: decoding an encrypted command-and-control channel

Posted by   Martijn Grooten on   Nov 3, 2017

Trickbot, a banking trojan which appeared this year, seems to be a new, more modular, and more extensible malware descendant of the notorious Dyre botnet trojan. At VB2017, Symantec researcher Andrew Brandt presented a walkthrough of a typical Trickbot infection process, and its aftermath, as seen through the lens of a tool used to perform man-in-the-middle decryption. Today, we publish both Andrew's slides and the recording of his presentation.

Read more  

Paper: FAME - Friendly Malware Analysis Framework

Posted by   Martijn Grooten on   Nov 2, 2017

Today, we publish a short paper in which CERT Société Générale presents FAME, its open source malware analysis framework.

Read more  

Ebury and Mayhem server malware families still active

Posted by   Martijn Grooten on   Oct 31, 2017

Ebury and Mayhem, two families of Linux server malware, about which VB published papers back in 2014, are still active and have received recent updates.

Read more  

VB2017 paper: Crypton - exposing malware's deepest secrets

Posted by   Martijn Grooten on   Oct 27, 2017

Crypton, a tool developed by F5 Networks researchers Julia Karpin and Anna Dorfman, aims to speed up the reverse engineering process by decrypting encrypted content found in a (malicious) binary. The researchers described the tool in a paper which they presented at VB2017 in Madrid. Today, we publish both the paper and the recording of their presentation.

Read more  

VB2017 paper: The sprawling market of consumer spyware

Posted by   Martijn Grooten on   Oct 25, 2017

For many people, the threat of an abusive partner or ex-partner is very real - and the market for consumer spyware worryingly large. Today, we publish the recording of a presentation on the subject of consumer spyware given at VB2017 by The Daily Beast reporter Joseph Cox.

Read more  

Gábor Szappanos wins fourth Péter Szőr Award

Posted by   Martijn Grooten on   Oct 23, 2017

At the VB2017 gala dinner, the fourth Péter Szőr Award was presented to Sophos researcher Gábor Szappanos for his paper "AKBuilder – the crowdsourced exploit kit".

Read more  

VB2017 paper: Walking in your enemy's shadow: when fourth-party collection becomes attribution hell

Posted by   Martijn Grooten on   Oct 20, 2017

We publish the VB2017 paper and video by Kaspersky Lab researchers Juan Andres Guerrero-Saade and Costin Raiu, in which they look at fourth-party collection (spies spying on other spies' campaigns) and its implications for attribution.

Read more  

Didn't come to VB2017? Tell us why!

Posted by   Martijn Grooten on   Oct 11, 2017

Virus Bulletin is a company - and a conference - with a mission: to further the research in and facilitate the fight against digital threats. To help us in this mission, we want to hear from those who didn't come to Madrid. What is your impression of the VB Conference? What did you think of this year's programme? And why couldn't you come to Madrid?

Read more  

Montreal will host VB2018

Posted by   Martijn Grooten on   Oct 10, 2017

Last week, we announced the full details of VB2018, which will take place 3-5 October 2018 at the Fairmont The Queen Elizabeth hotel in Montreal, Quebec, Canada.

Read more  

VB2017 preview: Beyond lexical and PDNS (guest blog)

Posted by   Virus Bulletin on   Oct 5, 2017

In a special guest blog post, VB2017 Silver sponsor Cisco Umbrella writes about a paper that researchers Dhia Mahjoub and David Rodriguez will present at the conference this Friday.

Read more  

Search blog

UN to curb spam within two years

UN aims to bring spam under control by 2007.
UN aims to bring spam under control by 2007. Representatives of the United Nation's International Telecommunications Union (ITU) meeting in Geneva this week as part of the World… https://www.virusbulletin.com/blog/2004/07/un-curb-spam-within-two-years/

International pact to fight spam

Countries join forces to declare war on spam.
Countries join forces to declare war on spam. Representatives from the US, the UK and Australia have signed a 'Memorandum of Understanding' (MoU) on spam. The agreement was… https://www.virusbulletin.com/blog/2004/07/international-pact-fight-spam/

Magold teen on probation

Hungarian virus writer convicted.
Hungarian virus writer convicted. A Hungarian teenager has been sentenced to two years' probation for creating the Magold virus. Earlier this week the Veszprem City Court… https://www.virusbulletin.com/blog/2004/07/magold-teen-probation/

July

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/07/

Patent filed for voice spam blocking technology

Technology to stamp out Internet telephony spam.
Technology to stamp out Internet telephony spam. A patent application has been filed for a method to identify and block SPIT - spam over Internet telephony, or VoIP spam. SPIT, or… https://www.virusbulletin.com/blog/2004/06/patent-filed-voice-spam-blocking-technology/

SMS spammer arrested

First Russian to be sentenced for sending spam.
First Russian to be sentenced for sending spam. Russian student Dmitry Anosov made history last month when he became the first Russian to be sentenced for sending spam - even… https://www.virusbulletin.com/blog/2004/06/sms-spammer-arrested/

7 steps to a spam-free existence?

Anti-virus and security related articles provided by independent anti-virus advisors, Virus Bulletin
"Stunning" survey results lead to seven-step guide. Email security firm Vircom has issued a seven-step guide to avoiding spam, after its six-month study revealed (shock, horror)… https://www.virusbulletin.com/blog/2004/06/7-steps-spam-free-existence/

Gates urges users to turn on auto-update

Microsoft chief says users must play their part in cutting down virus combat time.
Microsoft chief says users must play their part in cutting down virus combat time. Microsoft chief Bill Gates has pledged that the time taken for Microsoft to patch… https://www.virusbulletin.com/blog/2004/06/gates-urges-users-turn-auto-update/

Microsoft issues advice about critical vulnerability

Apply your patches and update your AV software.
Apply your patches and update your AV software. Microsoft has issued advice on what you should know about Download.Ject The Trojan downloader, also known as JS/Scob.A and Toofer,… https://www.virusbulletin.com/blog/2004/06/microsoft-issues-advice-about-critical-vulnerability/

AOL victim of inside spam job

AOL employee arrested.
AOL employee arrested. An AOL employee has been arrested and charged with selling the company's customer email list to spammers. 24-year-old AOL engineer Jason Smathers is accused… https://www.virusbulletin.com/blog/2004/06/aol-victim-inside-spam-job/

ISPs take responsibility

The six major ISPs of the Anti-Spam Technical Alliance say spam cannot be stopped unless they take action.
The six major ISPs of the Anti-Spam Technical Alliance say spam cannot be stopped unless they take action. Six major Internet Service Providers have put forward a joint proposal… https://www.virusbulletin.com/blog/2004/06/isps-take-responsibility/

Microsoft to buy NAI?

Rumours abound. NAI CEO denies them.
Rumours abound. NAI CEO denies them. Tech news website CRN reports that AV vendor Network Associates is up for sale, and that Microsoft is the likely lucky new owner. Although no… https://www.virusbulletin.com/blog/2004/06/microsoft-buy-nai/

Obituary: Marek Sell

On 12 June 2004 Marek Sell, creator of the Polish MkS_Vir anti-virus, died. Aleksander Czarnowksi looks back.
On 12 June 2004 Marek Sell, creator of the Polish MkS_Vir anti-virus, died. Aleksander Czarnowksi looks back. I met Marek somewhere around 1990, two years after he released the… https://www.virusbulletin.com/blog/2004/06/obituary-marek-sell/

AV going mobile

Mobile providers clamour to become the first to offer AV protection for mobile phones.
Mobile providers clamour to become the first to offer AV protection for mobile phones. Following the appearance of SymbOS/Cabir.A, the first virus capable of spreading via mobile… https://www.virusbulletin.com/blog/2004/06/av-going-mobile/

Sasser author jobseeking

Gis' a job! Name: Sven Jaschan. Age: 18. Previous work experience: creating and distributing Internet worm(s).
Gis' a job! Name: Sven Jaschan. Age: 18. Previous work experience: creating and distributing Internet worm(s). The lawyer representing Sven Jaschan, self-confessed author of the… https://www.virusbulletin.com/blog/2004/06/sasser-author-jobseeking/

Microsoft AV still on track

Not forgotten...
Not forgotten... Microsoft is still on track to offer its own anti-virus product, according to the chief of its security business unit. It has been a year since Microsoft… https://www.virusbulletin.com/blog/2004/06/microsoft-av-still-track/

FTC says no to 'Do Not Spam'

A 'Do Not Spam' list could actually increase spam levels, says FTC.
A 'Do Not Spam' list could actually increase spam levels, says FTC. The Federal Trade Commission (FTC) has told Congress that a national 'Do Not Spam' registry is not appropriate… https://www.virusbulletin.com/blog/2004/06/ftc-says-no-do-not-spam/

Virus calling

First mobile phone worm discovered.
First mobile phone worm discovered. The first worm to be capable of spreading via mobile phones has been discovered. The initial announcement of the proof-of-concept worm was… https://www.virusbulletin.com/blog/2004/06/virus-calling/

More spammers sued

Microsoft throws its weight around against spammers
Microsoft throws its weight around against spammers Microsoft has filed eight new lawsuits against spammers. All of the suits allege spoofing and falsifying of domain names.… https://www.virusbulletin.com/blog/2004/06/more-spammers-sued/

Virus cost MOD £10 million

Ministry of Defence reveals Lovgate found a weakness in its defences
Ministry of Defence reveals Lovgate found a weakness in its defences According to Computer Weekly the UK's Ministry of Defence (MOD) has revealed that, last year, it spent £10m on… https://www.virusbulletin.com/blog/2004/06/virus-cost-mod-10-million/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.